Назад
Company hidden
5 дней назад

Information Security & Risk Manager (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security & Risk Manager (Cybersecurity): Leading Empyrean’s ISO 27001 ISMS, security risk assessments, control evaluations, audit readiness, and remediation activities with an accent on governance, compliance, and assurance across cybersecurity and technology controls. Focus on coordinating audits and control testing, maintaining the enterprise risk register, evaluating control effectiveness, and managing remediation for complex technology and regulatory risks.

Location: Virtual, Houston, Texas, USA

Company

hirify.global operates an information security governance, risk, compliance, and assurance program supporting technology and regulated-environment requirements.

What you will do

  • Lead ISO 27001 certification, surveillance, internal audit readiness, and ongoing ISMS compliance activities.
  • Coordinate control testing, audits, assessments, and assurance activities across ISO 27001, SOC 2, NIST, HIPAA, and related frameworks.
  • Identify, assess, document, monitor, and communicate information security risks, control gaps, exceptions, and remediation plans.
  • Maintain the enterprise information security risk register and related issue, exception, and remediation documentation.
  • Evaluate cybersecurity, privacy, engineering, technology, third-party, and major-initiative risks and control effectiveness.
  • Prepare security responses for client questionnaires, RFPs, due-diligence requests, and internal inquiries while partnering with business, technology, Security, Privacy, and leadership stakeholders.

Requirements

  • 5+ years of experience in information security risk, governance, compliance, technology audit, security engineering, or a related area.
  • Prior security compliance, risk, or audit experience, particularly with ISO 27001.
  • Working knowledge of ISO 27001/ISMS, SOC 2/TSC, NIST CSF, NIST 800-53, NIST AI RMF, CIS, COBIT, and ITIL.
  • Experience evaluating cybersecurity, privacy, engineering, application, infrastructure, and technology controls.
  • Knowledge of vulnerability management, incident response, logging and monitoring, zero trust, SASE, insider threat, vendor risk management, PKI, penetration testing, and segregation of duties.
  • Strong communication, organization, analytical, documentation, and cross-functional collaboration skills.

Nice to have

  • Experience with SOC 2, HIPAA, FedRAMP, or similar frameworks.
  • Experience with ServiceNow, Jira, enterprise workflow, ticketing, directory, GRC, and security technologies.
  • CISA, CISM, CISSP, CIA, or ISO 27001 Lead Implementer/Lead Auditor certification or training.

Culture & Benefits

  • Cross-functional collaboration with business, technology, Security, Privacy, and leadership stakeholders.
  • Individual-contributor role with responsibility for security governance, risk, compliance, and assurance activities.
  • Work is performed virtually from Houston, Texas, USA.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →